package cn.js.controller;
import org.springframework.security.access.prepost.PreAuthorize;
import org.springframework.web.bind.annotation.RequestMapping;
import org.springframework.web.bind.annotation.RestController;

@RestController
public class HelloController {

    @RequestMapping("/hello")
    @PreAuthorize("hasAuthority('test')")//权限本身就是使用字符串进行管理
    public String hello(){
        return "hello";
    }


    @RequestMapping("/update")
    @PreAuthorize("hasAuthority('update')")//权限本身就是使用字符串进行管理
    public String update(){
        return "update";
    }
}
